<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>reevaluation Archives - Corsec Security, Inc.®</title>
	<atom:link href="https://www.corsec.com/tag/reevaluation/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.corsec.com/tag/reevaluation/</link>
	<description>Corsec helps companies complete security certifications and validations like FIPS 140-3, Common Criteria, CSfC, &#38; the DoDIN APL / UC APL.</description>
	<lastBuildDate>Fri, 21 Nov 2025 14:33:02 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.corsec.com/wp-content/uploads/cropped-Corsec-Logo-SiteMap-32x32.png</url>
	<title>reevaluation Archives - Corsec Security, Inc.®</title>
	<link>https://www.corsec.com/tag/reevaluation/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Security Certification Maintenance</title>
		<link>https://www.corsec.com/security-certification-maintenance/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Wed, 07 Dec 2016 20:16:07 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[UC APL]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[reevaluation]]></category>
		<category><![CDATA[Revalidation]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">https://www.corsec.com/?p=9400</guid>

					<description><![CDATA[<p>The post <a href="https://www.corsec.com/security-certification-maintenance/">Security Certification Maintenance</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="wpb-content-wrapper"><div class="vc_row wpb_row vc_row-fluid"><div class="wpb_column vc_column_container vc_col-sm-12"><div class="vc_column-inner"><div class="wpb_wrapper">
	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<p>As you release new versions of previously certified and validated products, it is crucial that you develop a security certification maintenance plan to keep up with the evolution of your technology. Corsec’s Maintenance and Compliance Service helps you determine whether a full re-evaluation is necessary, or if you can pursue other measures to continue generating revenue from your initial certification or validation.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5><strong>Security Certification Maintenance:</strong></h5>
<p>Each security certification has its own unique requirements for maintenance and renewal. Corsec’s engineering team helps you understand the specific actions you will need to take for each of their products and certifications.</p>
<p><a href="https://www.corsec.com/fips-140-2/"><span style="color: #008000;">FIPS 140-2</span></a><br />
The FIPS 140-2 validation process lists five change scenarios that are used to determine if a product requires revalidation, or if documentation alone can address the changes at issue. Corsec will help determine which scenario mostly closely aligns to the latest version of your product.</p>
<p><a href="https://www.corsec.com/common-criteria/"><span style="color: #ff6600;">Common Criteria</span></a><br />
Common Criteria determines re-evaluation through a process called Assurance Continuity (AC). If major changes have occurred in the security environment, evidence needs to be submitted to a laboratory and the product needs to be re-evaluated. If minor changes have occurred, a vendor can perform “Assurance Maintenance,” a report that is attached as an addendum to the original product certification, as long as it is within two years of the initial issuance date.</p>
<p><span style="color: #0000ff;"><a style="color: #0000ff;" href="https://www.corsec.com/dodin-apl/">DoDIN APL</a></span><br />
In order to maintain a listing on the DoDIN APL, you must complete a Desktop Review (DR) for each major product version. In such a review, a high-level assessment determines whether the product listing will simply be updated with the new version identifier, whether minimal testing must be performed on the new version prior to receiving an updated listing, or whether the product must undergo a new evaluation in its entirety.</p>

		</div>
	</div>

	<div class="wpb_text_column wpb_content_element" >
		<div class="wpb_wrapper">
			<h5><strong>Keep Products Market-Ready</strong></h5>
<p>Corsec helps ensure that our partners continue to benefit from the efforts they put in initially to get their products certified or validated. If you have questions on the requirements around your products’ recertification or revalidation, we can help determine the best path forward with little to no disruption of your revenue stream.</p>

		</div>
	</div>
</div></div></div></div>
</div><p>The post <a href="https://www.corsec.com/security-certification-maintenance/">Security Certification Maintenance</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Budgeting for Certifications: Avoid Cost Creep</title>
		<link>https://www.corsec.com/certification-budgeting/</link>
		
		<dc:creator><![CDATA[Jake Nelson]]></dc:creator>
		<pubDate>Thu, 30 May 2013 14:55:36 +0000</pubDate>
				<category><![CDATA[Common Criteria]]></category>
		<category><![CDATA[DoDIN APL]]></category>
		<category><![CDATA[FIPS 140-2]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Certification Process]]></category>
		<category><![CDATA[Certification ROI]]></category>
		<category><![CDATA[Certification Updates]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[IT security]]></category>
		<category><![CDATA[reevaluation]]></category>
		<category><![CDATA[Revalidation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Security Certifications]]></category>
		<guid isPermaLink="false">http://corsec.com/?p=6500</guid>

					<description><![CDATA[<p>Budgeting for a Common Criteria Certification can be difficult, but it’s not impossible. Understanding how to create your certification budget, and taking the necessary steps to follow through with that budget, can reduce your costs and simplify the certification process. We are frequently asked, “How much does certification cost...</p>
<p>The post <a href="https://www.corsec.com/certification-budgeting/">Budgeting for Certifications: Avoid Cost Creep</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Budgeting for <span style="color: #ff6600;"><a style="color: #ff6600;" href="http://www.corsec.com/common-criteria-services/common-criteria-faq/">Common Criteria,</a></span><span style="color: #339966;"> <a href="https://www.corsec.com/fips-140-2/">FIPS 140-2</a>,</span> and the<span style="color: #0000ff;"> <a href="https://www.corsec.com/dodin-apl/">DoDIN APL</a> </span>can be confusing and overwhelming, but with the right information and resources, you will start to uncover the path thats right for you.</p>
<p>Understanding how to create your certification budget, and taking the necessary steps to follow through with that budget, can reduce your costs and simplify the certification process. We are frequently asked, “How much does certification cost?” This is similar to asking, “How much does a car cost?” The real answer is, “It depends.”</p>
<p>The first step in understanding how to budget for certification is to fully understand the scope of your project. Certification costs vary widely depending upon that scope. If yours is too broad, you may be needlessly spending money on a certification that will not provide a good <a href="http://www.corsec.com/about-us/webinars/evaluating-return-on-investment/">return on investment</a>. If your scope is too narrow, you may fail to capitalize on <a href="http://www.corsec.com/2013/05/you-have-your-validation-now-use-it-to-sell/">the true value of certification</a>. Going through the process to properly identify the scope of your certification is the most important step to forming a meaningful budget for the project. Perhaps the key aspect in identifying the scope is determining the product or system to be evaluated. Once you’ve decided on a boundary or Target of the Evaluation (TOE) you will need to:</p>
<ol>
<li>Determine the path and options available to you. For FIPS 140-2, you have the option of 4 validation levels. For Common Criteria, you may chose to certify under a Protection Profile (PP) or an Evaluation Assurance Level (EAL). These options can be done in numerous countries around the globe. When listing on the the APL, you need to determine which STIGs apply to your product.</li>
<li>Determine if the product will need to be modified in any way in order to meet requirements and how those modifications fit into the current development plan.</li>
</ol>
<p>You have to go through the process to understand what you are certifying, and why, in order to understand what the budgetary requirements will be. Once you understand the scope of your certification process, you can begin to plan a reasonable budget. To start, make sure you cover all of the costs in your budget. Next, you must understand which parts of the budget are variable, and which parts are fixed. The following is a list of expenses that every good certification budget should include:</p>
<p>1. Documentation preparation</p>
<p>2. Project management costs</p>
<p>3. Development costs for algorithm testing/test case development/STIG testing/entropy supplement, etc.</p>
<p>4. Development costs for product modifications</p>
<p>5. Laboratory fees</p>
<p>6. Government fees</p>
<p>7. Testing-related travel expenses</p>
<p>8. Cost to distribute product to consultants and testing laboratories</p>
<p>Some of these costs will be “fixed price,” while others are not. Understanding how to assess these accurately is crucial to keeping “cost creep” under control. Properly scoped, this budget can be manageable and predictable. Focusing your budget on only one area of expenses, or failing to properly identify the scope your project, can result in a budget that continually expands throughout your certification effort.</p>
<p>For help getting started with yours, <a href="http://corsec.com/company/contact-us/" target="_blank" rel="noopener noreferrer">contact Corsec.</a></p>
<p>The post <a href="https://www.corsec.com/certification-budgeting/">Budgeting for Certifications: Avoid Cost Creep</a> appeared first on <a href="https://www.corsec.com">Corsec Security, Inc.®</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
